CN110741613A - 一种加密数据流的识别方法、设备、存储介质及系统 - Google Patents

一种加密数据流的识别方法、设备、存储介质及系统 Download PDF

Info

Publication number
CN110741613A
CN110741613A CN201780091924.9A CN201780091924A CN110741613A CN 110741613 A CN110741613 A CN 110741613A CN 201780091924 A CN201780091924 A CN 201780091924A CN 110741613 A CN110741613 A CN 110741613A
Authority
CN
China
Prior art keywords
authentication
core network
data
parameter
network equipment
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN201780091924.9A
Other languages
English (en)
Other versions
CN110741613B (zh
Inventor
唐海
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Guangdong Oppo Mobile Telecommunications Corp Ltd
Original Assignee
Guangdong Oppo Mobile Telecommunications Corp Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Guangdong Oppo Mobile Telecommunications Corp Ltd filed Critical Guangdong Oppo Mobile Telecommunications Corp Ltd
Publication of CN110741613A publication Critical patent/CN110741613A/zh
Application granted granted Critical
Publication of CN110741613B publication Critical patent/CN110741613B/zh
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/03Protecting confidentiality, e.g. by encryption
    • H04W12/033Protecting confidentiality, e.g. by encryption of the user plane, e.g. user's traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/16Implementing security features at a particular protocol layer
    • H04L63/166Implementing security features at a particular protocol layer at the transport layer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/10Connection setup
    • H04W76/12Setup of transport tunnels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/20Manipulation of established connections
    • H04W76/25Maintenance of established connections
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W76/00Connection management
    • H04W76/30Connection release
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W80/00Wireless network protocols or protocol adaptations to wireless operation
    • H04W80/02Data link layer protocols
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W80/00Wireless network protocols or protocol adaptations to wireless operation
    • H04W80/08Upper layer protocols
    • H04W80/10Upper layer protocols adapted for application session management, e.g. SIP [Session Initiation Protocol]

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

本发明实施例提供了一种加密数据流的识别方法、设备、可读存储介质及系统;该方法可以应用于核心网设备,所述方法包括:接收用户设备UE发送的承载有鉴权数据的数据包;其中,所述鉴权数据包括第一鉴权参数、第一鉴权结果以及应用标识;基于所述第一鉴权参数和第二鉴权参数,按照设定的鉴权算法获得第二鉴权结果;其中,所述第二鉴权参数为预存的所述应用标识对应的鉴权参数;当所述第二鉴权结果与所述第一鉴权结果比对一致时,则建立所述数据包的网络协议IP五元组与所述应用标识之间的关联关系;其中,所述关联关系用于后续对所述UE发送的与所述应用标识对应的加密数据流进行识别。

Description

PCT国内申请,说明书已公开。

Claims (33)

  1. PCT国内申请,权利要求书已公开。
CN201780091924.9A 2017-10-16 2017-10-16 一种加密数据流的识别方法、设备、存储介质及系统 Active CN110741613B (zh)

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2017/106349 WO2019075608A1 (zh) 2017-10-16 2017-10-16 一种加密数据流的识别方法、设备、存储介质及系统

Publications (2)

Publication Number Publication Date
CN110741613A true CN110741613A (zh) 2020-01-31
CN110741613B CN110741613B (zh) 2021-01-12

Family

ID=66173068

Family Applications (2)

Application Number Title Priority Date Filing Date
CN201780091924.9A Active CN110741613B (zh) 2017-10-16 2017-10-16 一种加密数据流的识别方法、设备、存储介质及系统
CN201880038900.1A Active CN110771116B (zh) 2017-10-16 2018-05-03 一种加密数据流的识别方法、设备、存储介质及系统

Family Applications After (1)

Application Number Title Priority Date Filing Date
CN201880038900.1A Active CN110771116B (zh) 2017-10-16 2018-05-03 一种加密数据流的识别方法、设备、存储介质及系统

Country Status (4)

Country Link
US (1) US11418951B2 (zh)
EP (1) EP3668043A4 (zh)
CN (2) CN110741613B (zh)
WO (2) WO2019075608A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113674455A (zh) * 2021-08-13 2021-11-19 京东科技信息技术有限公司 智能门锁远程控制方法、装置、系统、设备及存储介质

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DK3738331T3 (da) * 2018-04-05 2021-05-31 Ericsson Telefon Ab L M Konfigurering af radioressourcer
CN113193932B (zh) * 2019-09-27 2022-08-23 腾讯科技(深圳)有限公司 网络节点执行的方法以及相应的网络节点
CN112671661A (zh) * 2020-12-24 2021-04-16 广州市网优优信息技术开发有限公司 物联网数据传输方法及系统
CN118303054A (zh) * 2021-11-26 2024-07-05 Abb瑞士股份有限公司 用于在网络系统中进行设备调试的方法及网络系统

Citations (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050210234A1 (en) * 2004-03-17 2005-09-22 Best Fiona S Reach-back communications terminal with selectable networking options
CN101668016A (zh) * 2009-09-30 2010-03-10 华为技术有限公司 鉴权方法及装置
CN102893695A (zh) * 2010-05-13 2013-01-23 日本电气株式会社 网关设备、基站、移动管理服务器和通信方法
CN103414709A (zh) * 2013-08-02 2013-11-27 杭州华三通信技术有限公司 用户身份绑定、协助绑定的方法及装置
CN103596166A (zh) * 2012-08-13 2014-02-19 电信科学技术研究院 一种标识映射方法与设备及策略控制方法与系统
CN104038389A (zh) * 2014-06-19 2014-09-10 高长喜 多重应用协议识别方法和装置
CN105592449A (zh) * 2014-10-20 2016-05-18 中国电信股份有限公司 业务识别方法和系统
CN105915396A (zh) * 2016-06-20 2016-08-31 中国联合网络通信集团有限公司 家庭网络流量识别系统和方法
US20160262021A1 (en) * 2015-03-06 2016-09-08 Qualcomm Incorporated Sponsored connectivity to cellular networks using existing credentials
US20170126564A1 (en) * 2015-04-13 2017-05-04 Ajit Ramachandra Mayya Method and system of application-aware routing with crowdsourcing

Family Cites Families (21)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6948060B1 (en) * 2000-08-11 2005-09-20 Intel Corporation Method and apparatus for monitoring encrypted communication in a network
US7778194B1 (en) 2004-08-13 2010-08-17 Packeteer, Inc. Examination of connection handshake to enhance classification of encrypted network traffic
US7562211B2 (en) * 2005-10-27 2009-07-14 Microsoft Corporation Inspecting encrypted communications with end-to-end integrity
US8875236B2 (en) * 2007-06-11 2014-10-28 Nokia Corporation Security in communication networks
CN101714952B (zh) * 2009-12-22 2012-03-07 北京邮电大学 一种接入网的流量识别方法和装置
CN102111263A (zh) * 2011-02-21 2011-06-29 山东中孚信息产业股份有限公司 一种数据流加密的方法
CN102137022B (zh) * 2011-04-01 2013-11-06 华为技术有限公司 提供用于识别数据包的信息的方法、爬虫引擎及网络系统
CN103428643A (zh) * 2012-05-17 2013-12-04 大唐移动通信设备有限公司 一种动态重组方法及装置
EP2675203B1 (en) * 2012-06-11 2019-11-27 BlackBerry Limited Enabling multiple authentication applications
US9985967B2 (en) * 2013-05-29 2018-05-29 Telefonaktiebolaget Lm Ericsson (Publ) Gateway, client device and methods for facilitating communication between a client device and an application server
GB2518257A (en) * 2013-09-13 2015-03-18 Vodafone Ip Licensing Ltd Methods and systems for operating a secure mobile device
EP2890073A1 (en) * 2013-12-31 2015-07-01 Gemalto SA System and method for securing machine-to-machine communications
CN105099930B (zh) * 2014-05-21 2019-07-09 新华三技术有限公司 加密数据流流量控制方法及装置
KR101663401B1 (ko) * 2015-01-05 2016-10-06 주식회사 퓨쳐시스템 Ssl로 암호화된 패킷을 커널에서 분석하는 장치 및 방법
CN107317674B (zh) * 2016-04-27 2021-08-31 华为技术有限公司 密钥分发、认证方法,装置及系统
CN106209775B (zh) * 2016-06-24 2019-05-24 深圳信息职业技术学院 一种ssl加密网络流的应用类型识别方法与装置
US10530811B2 (en) * 2016-08-11 2020-01-07 Vm-Robot, Inc. Routing systems and methods
US10715510B2 (en) * 2017-01-16 2020-07-14 Citrix Systems, Inc. Secure device notifications from remote applications
US10630642B2 (en) * 2017-10-06 2020-04-21 Stealthpath, Inc. Methods for internet communication security
US10367811B2 (en) * 2017-10-06 2019-07-30 Stealthpath, Inc. Methods for internet communication security
US10397186B2 (en) * 2017-10-06 2019-08-27 Stealthpath, Inc. Methods for internet communication security

Patent Citations (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20050210234A1 (en) * 2004-03-17 2005-09-22 Best Fiona S Reach-back communications terminal with selectable networking options
CN101668016A (zh) * 2009-09-30 2010-03-10 华为技术有限公司 鉴权方法及装置
CN102893695A (zh) * 2010-05-13 2013-01-23 日本电气株式会社 网关设备、基站、移动管理服务器和通信方法
CN103596166A (zh) * 2012-08-13 2014-02-19 电信科学技术研究院 一种标识映射方法与设备及策略控制方法与系统
CN103414709A (zh) * 2013-08-02 2013-11-27 杭州华三通信技术有限公司 用户身份绑定、协助绑定的方法及装置
CN104038389A (zh) * 2014-06-19 2014-09-10 高长喜 多重应用协议识别方法和装置
CN105592449A (zh) * 2014-10-20 2016-05-18 中国电信股份有限公司 业务识别方法和系统
US20160262021A1 (en) * 2015-03-06 2016-09-08 Qualcomm Incorporated Sponsored connectivity to cellular networks using existing credentials
US20170126564A1 (en) * 2015-04-13 2017-05-04 Ajit Ramachandra Mayya Method and system of application-aware routing with crowdsourcing
CN105915396A (zh) * 2016-06-20 2016-08-31 中国联合网络通信集团有限公司 家庭网络流量识别系统和方法

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
OPPO: "Solution for UE assisted encrypted traffic detection", 《3GPP TSG SA WG2 MEETING #127 S2-181974》 *
OPPO: "Solution for UE assisted encrypted traffic detection", 《3GPP TSG SA WG2 MEETING #127 S2-183209》 *
OPPO: "Solution for UE assisted encrypted traffic detection", 《3GPP TSG SA WG2 MEETING #127 S2-184009》 *
SOLUTION FOR UE ASSISTED ENCRYPTED TRAFFIC DETECTION: "OPPO", 《3GPP TSG SA WG2 MEETING #127 S2-180376》 *

Cited By (2)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN113674455A (zh) * 2021-08-13 2021-11-19 京东科技信息技术有限公司 智能门锁远程控制方法、装置、系统、设备及存储介质
CN113674455B (zh) * 2021-08-13 2023-08-04 京东科技信息技术有限公司 智能门锁远程控制方法、装置、系统、设备及存储介质

Also Published As

Publication number Publication date
EP3668043A1 (en) 2020-06-17
CN110741613B (zh) 2021-01-12
CN110771116A (zh) 2020-02-07
EP3668043A4 (en) 2020-10-07
CN110771116B (zh) 2021-02-26
US11418951B2 (en) 2022-08-16
WO2019075608A1 (zh) 2019-04-25
WO2019076000A1 (zh) 2019-04-25
US20200245136A1 (en) 2020-07-30

Similar Documents

Publication Publication Date Title
US11038846B2 (en) Internet protocol security tunnel maintenance method, apparatus, and system
CN110741613A (zh) 一种加密数据流的识别方法、设备、存储介质及系统
US10069800B2 (en) Scalable intermediate network device leveraging SSL session ticket extension
US20190123909A1 (en) End-to-End Service Layer Authentication
EP3000249B1 (en) Access network assisted bootstrapping
US11101978B2 (en) Establishing and managing identities for constrained devices
CN109936529B (zh) 一种安全通信的方法、装置和系统
CN107483383B (zh) 一种数据处理方法、终端、后台服务器及存储介质
CN114503507A (zh) 安全的发布-订阅通信方法和设备
TW201644291A (zh) 用於使用特定於應用的網路存取身份碼來進行到無線網路的受贊助連接的設備和方法(一)
EP3068093B1 (en) Security authentication method and bidirectional forwarding detection method
EP3300331A1 (en) Response method, apparatus and system in virtual network computing authentication, and proxy server
US8091122B2 (en) Computer program product, apparatus and method for secure HTTP digest response verification and integrity protection in a mobile terminal
TW201706900A (zh) 終端的認證處理、認證方法及裝置、系統
TW201644292A (zh) 用於使用特定於應用的網路存取身份碼來進行到無線網路的受贊助連接的設備和方法(二)
US10484869B2 (en) Generic bootstrapping architecture protocol
WO2017031691A1 (zh) 业务处理方法及装置
CN111083091B (zh) 一种隧道的创建方法、装置及存储介质
WO2022083433A1 (zh) 会话请求方法、装置、终端及存储介质
CN110474922B (zh) 一种通信方法、pc系统及接入控制路由器
CN112087412B (zh) 一种基于唯一令牌的服务访问处理方法及装置
CN113938474B (zh) 一种虚拟机访问方法、装置、电子设备和存储介质
CN104737571B (zh) 保护在通信网络中发送的有效载荷
EP4221078A1 (en) Packet processing method and apparatus
WO2019076025A1 (zh) 一种加密数据流的识别方法、设备、存储介质及系统

Legal Events

Date Code Title Description
PB01 Publication
PB01 Publication
SE01 Entry into force of request for substantive examination
SE01 Entry into force of request for substantive examination
GR01 Patent grant
GR01 Patent grant